![]() |
|
Plagegeister aller Art und deren Bekämpfung: Windows 7: C:/Trojan:Win32/Wysotot!InkWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #11 |
| ![]() Windows 7: C:/Trojan:Win32/Wysotot!Ink Also der Online Scaner hatte 3 Funde, habe wie geschrieben nichts gelöscht, (nur Ergebnis gepostet) und Mozilla als Browser funtioniert nicht. Sonst bis jetzt keine Probleme mehr erkennbar. gruß Faxikus B]C:/EsetOnlineScaner.txt:[/B] ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=7e8a6d5ccf793443ad19c81694986939 # engine=18213 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-10 10:44:01 # local_time=2014-05-11 12:44:01 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 23424924 151391691 0 0 # scanned=210770 # found=3 # cleaned=0 # scan_time=9839 sh=628B8082320DB416922488A6F7871061EDDCDE5E ft=1 fh=ab55c892c6bdec01 vn="Win32/SpeedingUpMyPC.J Anwendung" ac=I fn="C:\Users\Pippifax\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAFQ6KTF\OptimizerPro[1].exe" sh=628B8082320DB416922488A6F7871061EDDCDE5E ft=1 fh=ab55c892c6bdec01 vn="Win32/SpeedingUpMyPC.J Anwendung" ac=I fn="C:\Users\Pippifax\AppData\Local\Temp\optimizerpro.exe" sh=095355B5F6407556A930974E561011A3EFFB9A73 ft=1 fh=85adefd70ea34ad2 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Pippifax\AppData\Local\Temp\setup.exe" C:/Checkup.txt Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.206 Google Chrome 34.0.1847.116 Google Chrome 34.0.1847.131 ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials msseces.exe Windows Defender MSMpEng.exe Common Files Microsoft Shared Windows Live Intel.SmallBusinessAdvantage.WindowsService.exe -?- `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` C:/FRST.txt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 Ran by Pippifax (administrator) on PIPPIFAX-THINK on 11-05-2014 10:30:05 Running from C:\Users\Pippifax\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [178960 2012-03-15] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11407120 2012-03-27] (Intel Corporation) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1654400 2012-02-21] (Conexant Systems, Inc.) HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [382528 2012-02-25] (Lenovo.) HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [290160 2012-06-01] (Lenovo Group Limited) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-02-26] (Intel(R) Corporation) HKLM\...\Run: [] => [X] HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-03-07] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-04-13] (Intel Corporation) HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.) HKLM-x32\...\Run: [IntelSBA] => C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe [4243168 2012-04-23] (Intel Corporation) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2008-12-24] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePDRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl8] => C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD8LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-03-12] (CyberLink Corp.) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.) HKLM-x32\...\Run: [Conime] => %windir%\system32\conime.exe HKLM-x32\...\Run: [SPStatusMonitor] => C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe [2778016 2012-11-14] (Samsung) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\Run: [GoogleChromeAutoLaunch_2814A6EC815B16EF397FE9F43BF95EB7] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032 2014-04-24] (Google Inc.) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\MountPoints2: {6f751c26-4664-11e2-bc78-806e6f6e6963} - Q:\LenovoQDrive.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll No File BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files (x86)\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files\Lenovo Fingerprint Reader\npffwloplugin.dll (AuthenTec, Inc) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Shopping Helper Smartbar - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\{4d0d6d2c-42a1-e9d7-e187-3f1847b7305f} [2014-03-13] FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] Chrome: ======= CHR HomePage: CHR StartupUrls: "http://www.trojaner-board.de/" CHR Extension: (Newhub) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoejbmmillcdifgagjpdlaamnalbielp [2014-03-14] CHR Extension: (Google Docs) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-14] CHR Extension: (Google Drive) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-14] CHR Extension: (YouTube) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-14] CHR Extension: (Website Logon) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\clglhglbidpdbjffpfcldkifhdegdfle [2014-03-14] CHR Extension: (Google-Suche) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-14] CHR Extension: (Google Wallet) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-14] CHR Extension: (Google Mail) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-14] CHR HKLM\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKCU\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [clglhglbidpdbjffpfcldkifhdegdfle] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx [2013-04-01] ==================== Services (Whitelisted) ================= R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.) R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo) R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2139944 2013-08-07] (AuthenTec, Inc) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-07] () R2 Intel(R) Small Business Advantage; C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [46816 2012-04-23] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-07] (Intel Corporation) R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-25] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] () R2 Samsung AiO Network Discovery Service; C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe [395168 2012-11-14] (Samsung) R2 Samsung AIO Status Monitor Service; C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe [722336 2012-11-14] (Samsung) R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [503344 2013-01-14] (Samsung Electronics Co., Ltd.) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401704 2013-07-22] (AuthenTec, Inc.) R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) R2 SAService; %SystemRoot%\system32\SAsrv.exe [X] ==================== Drivers (Whitelisted) ==================== S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27448 2012-06-19] (Synaptics Incorporated) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility) R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61112 2014-03-18] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-11 10:27 - 2014-05-11 10:27 - 00855379 _____ () C:\Users\Pippifax\Desktop\SecurityCheck.exe 2014-05-10 21:53 - 2014-05-10 21:53 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-10 21:50 - 2014-05-10 21:50 - 02347384 _____ (ESET) C:\Users\Pippifax\Downloads\esetsmartinstaller_deu.exe 2014-05-09 22:50 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-09 22:50 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-09 22:50 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-09 22:50 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-09 22:20 - 2014-05-11 10:29 - 00000000 ____D () C:\Users\Pippifax\Desktop\FRST-OlderVersion 2014-05-09 22:17 - 2014-05-09 22:17 - 00001419 _____ () C:\Users\Pippifax\Desktop\JRT.txt 2014-05-09 22:08 - 2014-05-09 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-05-09 22:07 - 2014-05-09 22:08 - 01016261 _____ (Thisisu) C:\Users\Pippifax\Downloads\JRT.exe 2014-05-09 21:59 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-09 21:58 - 2014-05-09 22:00 - 00000000 ____D () C:\AdwCleaner 2014-05-09 21:55 - 2014-05-09 21:55 - 01316991 _____ () C:\Users\Pippifax\Downloads\adwcleaner.exe 2014-05-09 21:53 - 2014-05-09 21:53 - 00000273 _____ () C:\Users\Pippifax\Desktop\mbam.txt 2014-05-09 21:48 - 2014-05-09 21:48 - 00706696 _____ () C:\Users\Pippifax\Downloads\Nicht bestätigt 95849.crdownload 2014-05-09 21:20 - 2014-05-09 21:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-09 21:20 - 2014-05-09 21:20 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-09 21:20 - 2014-05-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:20 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-09 21:19 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-09 21:19 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-09 21:19 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-09 21:18 - 2014-05-09 21:19 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Pippifax\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-09 21:16 - 2014-05-09 21:16 - 00340480 _____ () C:\Users\Pippifax\Downloads\Setup__4227_il891497.exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (6).exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-05-09 21:09 - 2014-05-09 21:10 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-05-09 21:06 - 2014-05-09 21:06 - 00495104 _____ () C:\Users\Pippifax\Downloads\test (3).exe 2014-04-25 22:44 - 2014-04-25 22:44 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-25 22:41 - 2014-04-25 22:42 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-25 22:40 - 2014-05-11 10:20 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-04-24 20:46 - 2014-04-24 20:46 - 00001275 _____ () C:\Users\Pippifax\Desktop\Revo Uninstaller.lnk 2014-04-24 20:46 - 2014-04-24 20:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95.exe 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95 (1).exe 2014-04-24 20:41 - 2014-04-24 20:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-23 23:56 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-23 23:56 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-23 23:56 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-23 23:56 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-23 23:56 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-23 23:56 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-23 23:56 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-23 23:56 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-23 23:56 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-23 23:56 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-23 23:56 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-23 23:56 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-23 23:55 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-23 23:55 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-23 23:55 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-23 23:55 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-23 23:55 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-23 23:55 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-23 23:55 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-23 23:55 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-23 23:55 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-23 23:55 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-23 23:55 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-23 23:55 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-23 23:55 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-23 23:55 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-23 23:55 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-23 23:55 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-23 23:55 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-23 23:55 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-23 23:55 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-23 23:55 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-23 23:55 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-23 23:55 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-23 23:55 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-23 23:55 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-23 23:55 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-23 23:55 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-23 23:55 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-23 23:55 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-23 23:55 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-23 23:55 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-23 23:55 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-23 23:55 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-23 23:40 - 2014-05-09 22:42 - 00021793 _____ () C:\Users\Pippifax\Desktop\Addition.txt 2014-04-23 23:38 - 2014-05-11 10:30 - 00022322 _____ () C:\Users\Pippifax\Desktop\FRST.txt 2014-04-23 23:38 - 2014-05-11 10:30 - 00000000 ____D () C:\FRST 2014-04-23 23:37 - 2014-05-11 10:29 - 02066432 _____ (Farbar) C:\Users\Pippifax\Desktop\FRST64.exe 2014-04-23 23:28 - 2014-05-09 22:01 - 00003142 _____ () C:\Windows\PFRO.log 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-05-11 10:19 - 00000504 _____ () C:\Windows\setupact.log 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log ==================== One Month Modified Files and Folders ======= 2014-05-11 10:30 - 2014-04-23 23:38 - 00022322 _____ () C:\Users\Pippifax\Desktop\FRST.txt 2014-05-11 10:30 - 2014-04-23 23:38 - 00000000 ____D () C:\FRST 2014-05-11 10:29 - 2014-05-09 22:20 - 00000000 ____D () C:\Users\Pippifax\Desktop\FRST-OlderVersion 2014-05-11 10:29 - 2014-04-23 23:37 - 02066432 _____ (Farbar) C:\Users\Pippifax\Desktop\FRST64.exe 2014-05-11 10:27 - 2014-05-11 10:27 - 00855379 _____ () C:\Users\Pippifax\Desktop\SecurityCheck.exe 2014-05-11 10:27 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-11 10:27 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-11 10:24 - 2012-12-15 13:57 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-05-11 10:24 - 2012-12-15 13:57 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-05-11 10:24 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-11 10:22 - 2012-12-15 05:12 - 02040653 _____ () C:\Windows\WindowsUpdate.log 2014-05-11 10:21 - 2014-03-14 11:00 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-11 10:21 - 2012-12-15 05:14 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-05-11 10:20 - 2014-04-25 22:40 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-05-11 10:20 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\system32\rpcnetp.exe 2014-05-11 10:20 - 2013-03-07 10:20 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-11 10:19 - 2014-04-23 19:43 - 00000504 _____ () C:\Windows\setupact.log 2014-05-11 10:19 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.exe 2014-05-11 10:19 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.dll 2014-05-11 10:19 - 2013-03-07 10:53 - 00000000 ____D () C:\ProgramData\Samsung Inkjet 2014-05-11 10:19 - 2013-03-02 22:51 - 00069792 _____ (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll 2014-05-11 10:19 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-11 09:10 - 2014-03-14 11:00 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-11 01:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-10 21:53 - 2014-05-10 21:53 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-10 21:50 - 2014-05-10 21:50 - 02347384 _____ (ESET) C:\Users\Pippifax\Downloads\esetsmartinstaller_deu.exe 2014-05-09 22:42 - 2014-04-23 23:40 - 00021793 _____ () C:\Users\Pippifax\Desktop\Addition.txt 2014-05-09 22:20 - 2013-03-07 10:20 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-09 22:20 - 2013-03-07 10:20 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-09 22:20 - 2013-03-07 10:20 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-09 22:17 - 2014-05-09 22:17 - 00001419 _____ () C:\Users\Pippifax\Desktop\JRT.txt 2014-05-09 22:08 - 2014-05-09 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-05-09 22:08 - 2014-05-09 22:07 - 01016261 _____ (Thisisu) C:\Users\Pippifax\Downloads\JRT.exe 2014-05-09 22:01 - 2014-04-23 23:28 - 00003142 _____ () C:\Windows\PFRO.log 2014-05-09 22:00 - 2014-05-09 21:58 - 00000000 ____D () C:\AdwCleaner 2014-05-09 21:55 - 2014-05-09 21:55 - 01316991 _____ () C:\Users\Pippifax\Downloads\adwcleaner.exe 2014-05-09 21:53 - 2014-05-09 21:53 - 00000273 _____ () C:\Users\Pippifax\Desktop\mbam.txt 2014-05-09 21:50 - 2014-05-09 21:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-09 21:48 - 2014-05-09 21:48 - 00706696 _____ () C:\Users\Pippifax\Downloads\Nicht bestätigt 95849.crdownload 2014-05-09 21:42 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2014-05-09 21:20 - 2014-05-09 21:20 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-09 21:20 - 2014-05-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-09 21:20 - 2014-05-09 21:19 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-09 21:19 - 2014-05-09 21:18 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Pippifax\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-09 21:16 - 2014-05-09 21:16 - 00340480 _____ () C:\Users\Pippifax\Downloads\Setup__4227_il891497.exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (6).exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-05-09 21:14 - 2014-03-14 11:00 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-09 21:13 - 2013-12-06 11:12 - 00000000 ____D () C:\ldiag 2014-05-09 21:13 - 2012-12-15 05:42 - 00000000 ____D () C:\Windows\System32\Tasks\TVT 2014-05-09 21:13 - 2012-12-15 05:23 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools 2014-05-09 21:13 - 2012-12-15 05:19 - 00000000 ____D () C:\Program Files (x86)\Lenovo 2014-05-09 21:13 - 2012-12-14 21:43 - 00000000 ____D () C:\ProgramData\Lenovo 2014-05-09 21:10 - 2014-05-09 21:09 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-05-09 21:06 - 2014-05-09 21:06 - 00495104 _____ () C:\Users\Pippifax\Downloads\test (3).exe 2014-05-09 21:05 - 2014-03-14 11:00 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 21:05 - 2014-03-14 11:00 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-29 16:01 - 2014-05-09 22:50 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 15:40 - 2014-05-09 22:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-29 14:48 - 2014-05-09 22:50 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-29 14:34 - 2014-05-09 22:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-25 22:44 - 2014-04-25 22:44 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-25 22:42 - 2014-04-25 22:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-24 21:07 - 2014-03-13 13:59 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-04-24 20:46 - 2014-04-24 20:46 - 00001275 _____ () C:\Users\Pippifax\Desktop\Revo Uninstaller.lnk 2014-04-24 20:46 - 2014-04-24 20:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95.exe 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95 (1).exe 2014-04-24 20:41 - 2014-04-24 20:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-24 20:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-21 21:02 - 2013-02-14 18:11 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\Adobe Some content of TEMP: ==================== C:\Users\Pippifax\AppData\Local\Temp\1_Offer_5.exe C:\Users\Pippifax\AppData\Local\Temp\amsetup_activeris_default_010414_installer.exe C:\Users\Pippifax\AppData\Local\Temp\f978377c-b7d4-4536-8e10-14ca97b13394.exe C:\Users\Pippifax\AppData\Local\Temp\instract.exe C:\Users\Pippifax\AppData\Local\Temp\mainapp.exe C:\Users\Pippifax\AppData\Local\Temp\mediaplayerpluus.exe C:\Users\Pippifax\AppData\Local\Temp\nsa95FC.exe C:\Users\Pippifax\AppData\Local\Temp\nsaAB52.exe C:\Users\Pippifax\AppData\Local\Temp\nsaE6C2.exe C:\Users\Pippifax\AppData\Local\Temp\nsi5FC0.exe C:\Users\Pippifax\AppData\Local\Temp\nsqDA52.exe C:\Users\Pippifax\AppData\Local\Temp\nsqE0B9.exe C:\Users\Pippifax\AppData\Local\Temp\nsv9F50.exe C:\Users\Pippifax\AppData\Local\Temp\optimizerpro.exe C:\Users\Pippifax\AppData\Local\Temp\Quarantine.exe C:\Users\Pippifax\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Pippifax\AppData\Local\Temp\setup.exe C:\Users\Pippifax\AppData\Local\Temp\spidentifierimpl.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-11 00:58 ==================== End Of Log ============================ |
Themen zu Windows 7: C:/Trojan:Win32/Wysotot!Ink |
alter, brauch, essen, fenster, firefox, freund, google, kleine, meldungen, microsoft, mozilla, natürlich, nutzen, private, schonmal, security, spyware, trojaner, verlauf, verschiedene, webseite, win, windows, windows 7, öffnen |